Improper Access Control in Intel FPGA SDK for OpenCL with Quartus Prime Pro Edition
CVE-2022-34157
6.7MEDIUM
Key Information:
- Vendor
- Intel
- Vendor
- CVE Published:
- 16 February 2023
Summary
The Intel FPGA SDK for OpenCL, specifically with the Quartus Prime Pro Edition software prior to version 22.1, contains a vulnerability related to improper access control. This flaw enables authenticated users to potentially escalate their privileges through local access. Malicious actors could exploit this weakness to gain unauthorized control over sensitive system resources, posing a significant risk to operational integrity.
Affected Version(s)
Intel(R) FPGA SDK for OpenCL(TM) with Intel(R) Quartus(R) Prime Pro Edition software before version 22.1
References
CVSS V3.1
Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved